Personal Agent Protocol was announced on October 6, 2026 by Sierra and Meta, together with Genesys, Instinct, Rocket, Shopify, Stripe and Walmart. It is an open standard that defines how personal AI agents interact with businesses: how they authenticate, what access they get, and how companies see what they did. Anyone can implement it. The problem it targets is not whether agents are smart enough, but why a business should let one in when it acts on a customer's behalf.
Where personal agents get stuck today
Most personal agents currently use websites and apps the way people do — loading pages and clicking through forms, and falling back to a support call or web chat when that fails. It is slow and often ends halfway. A direct connection could finish the same task securely in seconds, but only if all three sides are comfortable: consumers want speed and trust, brands want visibility and control, and agent builders want one consistent way in. Without shared rules, each company defends itself alone, and the default answer is to block agents altogether.
The protocol draws the lines first
Its principle is a clear split of authority: consumers decide what access their agent gets, and companies decide what agents may do on their turf. An agent starts on the company's website, discovers what is offered and how to reach it, and can begin as a guest to check availability or a returns policy. When a task needs the customer's account, the customer signs in on the company's page or uses credentials already set up with the agent. Sessions are built on OAuth, so questions asked before sign-in and an order change made afterward count as one visit, and the customer always holds the switch between read-only and write access. The work itself can travel three routes: the company's existing website, interfaces built on standards such as MCP and OpenAPI, or the company's own agent for conversational tasks like warranty claims.
The roadmap only reaches v0.1
This is still early: the group plans to publish the v0.1 specification later this month, host design workshops and release a reference implementation. Ideas beyond that include finer-grained permissions, push notifications when a flight is delayed or an order ships, and payment extensions that let an agent complete a purchase without sharing card details. For merchants like Shopify and Walmart, joining early means writing the rules for agent-driven shopping before agents arrive through scrapers and simulated clicks — a front door with access control instead. For users, the thing to watch is whether the permission switch really stays in their hands, rather than becoming one more unread consent dialog.